The identity and technical contract details declared by the specification.
CIAppGroupByTotal
A resulting object to put the given computes in over all the matching records.
ObservabilityPipelineAmazonOpenSearchDestinationType
string
The destination type. The value should always be amazonopensearch.
ObservabilityPipelineNewRelicDestination
object
The newrelic destination sends logs to the New Relic platform.
4 properties
4 required
ObservabilityPipelineHttpServerSourceAuthStrategy
string
HTTP authentication method.
CIAppPipelineEventPipelineInProgressStatus
string
The in progress status of the pipeline.
ObservabilityPipelineRemoveFieldsProcessorType
string
The processor type. The value should always be removefields.
ObservabilityPipelineSensitiveDataScannerProcessorCustomPattern
object
Defines a custom regex-based pattern for identifying sensitive data in logs.
2 properties
2 required
ObservabilityPipelineRsyslogSource
object
The rsyslog source listens for logs over TCP or UDP from an rsyslog server using the syslog protocol.
4 properties
3 required
ObservabilityPipelineFluentdSource
object
The fluentd source ingests logs from a Fluentd-compatible service.
3 properties
2 required
CIAppComputeType
string
The type of compute.
ObservabilityPipelineSplunkHecDestinationEncoding
string
Encoding format for log events.
CIAppPipelinesAggregationBucketsResponse
object
The query results.
1 property
ObservabilityPipelineFluentBitSource
object
The fluentbit source ingests logs from Fluent Bit.
3 properties
2 required
ObservabilityPipelineRenameFieldsProcessorType
string
The processor type. The value should always be renamefields.
ObservabilityPipelineLogstashSourceType
string
The source type. The value should always be logstash.
CIAppPipelineEventParameters
object
A map of key-value parameters or environment variables that were defined for the pipeline.
CIAppPipelineEventPipelineStatus
string
The final status of the pipeline.
CIAppPipelineEventStageStatus
string
The final status of the stage.
ObservabilityPipelineSumoLogicSource
object
The sumologic source receives logs from Sumo Logic collectors.
2 properties
2 required
CIAppPipelineEventTags
array
A list of user-defined tags. The tags must follow the key:value pattern.
ObservabilityPipelineGeneratedMetric
object
Defines a log-based custom metric, including its name, type, filter, value computation strategy, and optional grouping fields.
5 properties
4 required
UsageTimeSeriesObject
object
Usage timeseries data.
2 properties
ObservabilityPipelineHttpClientSourceAuthStrategy
string
Optional authentication strategy for HTTP requests.
CIAppGroupByMissing
The value to use for logs that don't have the facet used to group-by.
CIAppPipelineEventMetrics
array
A list of user-defined metrics. The metrics must follow the key:value pattern and the value must be numeric.
CIAppCompute
object
A compute rule to compute metrics or timeseries.
4 properties
1 required
ObservabilityPipelineGoogleChronicleDestination
object
The googlechronicle destination sends logs to Google Chronicle.
7 properties
5 required
ObservabilityPipelineSensitiveDataScannerProcessorActionHashAction
string
Action type that replaces the matched sensitive data with a hashed representation, preserving structure while securing content.
ObservabilityPipelineOcsfMapperProcessorMapping
object
Defines how specific events are transformed to OCSF using a mapping configuration.
2 properties
2 required
CIAppPipelineEventStepLevel
string
Used to distinguish between pipelines, stages, jobs and steps.
MicrosoftSentinelDestinationType
string
The destination type. The value should always be microsoftsentinel.
AzureStorageDestination
object
The azurestorage destination forwards logs to an Azure Blob Storage container.
5 properties
4 required
ObservabilityPipelineSensitiveDataScannerProcessorRule
object
Defines a rule for detecting sensitive data, including matching pattern, scope, and the action to take.
6 properties
5 required
ObservabilityPipelineHttpClientSourceType
string
The source type. The value should always be httpclient.
ObservabilityPipelineEnrichmentTableFileKeyItemsComparison
string
Defines how to compare key fields for enrichment table lookups.
ObservabilityPipelineQuotaProcessorLimit
object
The maximum amount of data or number of events allowed before the quota is enforced. Can be specified in bytes or events.
2 properties
2 required
CIAppGitInfo
object
If pipelines are triggered due to actions to a Git repository, then all payloads must contain this. Note that either tag or branch has to be provided, but not…
12 properties
3 required
CIAppPipelineEventStage
object
Details of a CI stage.
16 properties
8 required
ObservabilityPipelineParseGrokProcessorRuleMatchRule
object
Defines a Grok parsing rule, which extracts structured fields from log content using named Grok patterns. Each rule must have a unique name and a valid Datadog…
2 properties
2 required
ObservabilityPipelineKafkaSource
object
The kafka source ingests data from Apache Kafka topics.
7 properties
4 required
ListPipelinesResponse
object
Represents the response payload containing a list of pipelines and associated metadata.
2 properties
1 required
ObservabilityPipelineHttpServerSource
object
The httpserver source collects logs over HTTP POST from external services.
5 properties
4 required
CIAppPipelineEventJob
object
Details of a CI job.
19 properties
9 required
CIAppPipelineEventInProgressPipeline
object
Details of a running pipeline.
19 properties
7 required
ObservabilityPipelineRsyslogSourceType
string
The source type. The value should always be rsyslog.
ObservabilityPipelineSplunkTcpSource
object
The splunktcp source receives logs from a Splunk Universal Forwarder over TCP. TLS is supported for secure transmission.
3 properties
2 required
ObservabilityPipelineParseJSONProcessor
object
The parsejson processor extracts JSON from a specified field and flattens it into the event. This is useful when logs contain embedded JSON as a string.
5 properties
5 required
ObservabilityPipelineOcsfMappingLibrary
string
Predefined library mappings for common log formats.
CIAppCreatePipelineEventRequest
object
Request object.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternType
string
Indicates that a predefined library pattern is used.
ObservabilityPipelineOpenSearchDestinationType
string
The destination type. The value should always be opensearch.
ObservabilityPipelineSensitiveDataScannerProcessor
object
The sensitivedatascanner processor detects and optionally redacts sensitive data in log events.
5 properties
5 required
CIAppPipelineEventTypeName
string
Type of the event.
ObservabilityPipelineDatadogLogsDestinationType
string
The destination type. The value should always be datadoglogs.
CIAppGroupByTotalNumber
number
A number to use as the key value for the total bucket.
ObservabilityPipelineSensitiveDataScannerProcessorType
string
The processor type. The value should always be sensitivedatascanner.
CIAppAggregateBucketValueSingleNumber
number
A single number value.
CIAppWarning
object
A warning message indicating something that went wrong with the query.
3 properties
ObservabilityPipelineKafkaSourceSasl
object
Specifies the SASL mechanism for authenticating with a Kafka cluster.
1 property
ObservabilityPipelineSplunkHecDestination
object
The splunkhec destination forwards logs to Splunk using the HTTP Event Collector (HEC).
7 properties
3 required
CIAppAggregateSort
object
A sort rule. The aggregation field is required when type is measure.
4 properties
ObservabilityPipelineGeneratedMetricIncrementByFieldStrategy
string
Uses a numeric field in the log event as the metric increment.
ObservabilityPipelineElasticsearchDestination
object
The elasticsearch destination writes logs to an Elasticsearch cluster.
5 properties
3 required
ObservabilityPipelineHttpClientSource
object
The httpclient source scrapes logs from HTTP endpoints at regular intervals.
7 properties
3 required
ObservabilityPipelineSampleProcessor
object
The sample processor allows probabilistic sampling of logs at a fixed rate.
6 properties
4 required
CIAppPipelinesGroupBy
object
A group-by rule.
6 properties
1 required
CIAppComputes
object
A map of the metric name to value for regular compute, or a list of values for a timeseries.
ObservabilityPipelineSpec
object
Input schema representing an observability pipeline configuration. Used in create and validate requests.
1 property
1 required
CIAppPipelineEventsResponse
object
Response object with all pipeline events matching the request and pagination information.
3 properties
ObservabilityPipelineGooglePubSubSourceType
string
The source type. The value should always be googlepubsub.
ObservabilityPipelineData
object
Contains the pipeline’s ID, type, and configuration attributes.
3 properties
3 required
ObservabilityPipelineDedupeProcessorMode
string
The deduplication mode to apply to the fields.
HourlyUsageType
string
Usage type that is being measured.
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternType
string
Indicates a custom regular expression is used for matching.
ObservabilityPipelineAmazonDataFirehoseSource
object
The amazondatafirehose source ingests logs from AWS Data Firehose.
4 properties
2 required
ObservabilityPipelineReduceProcessorMergeStrategy
object
Defines how a specific field should be merged across grouped events.
2 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeIncludeTarget
string
Applies the rule only to included fields.
CIAppGroupByMissingNumber
number
The missing value to use if there is a number valued facet.
CIAppCreatePipelineEventRequestAttributesResource
Details of the CI pipeline event.
CIAppCIError
object
Contains information of the CI error.
4 properties
ObservabilityPipelineGenerateMetricsProcessor
object
The generatedatadogmetrics processor creates custom metrics from logs and sends them to Datadog. Metrics can be counters, gauges, or distributions and optional…
5 properties
5 required
ObservabilityPipelineGcpAuth
object
GCP credentials used to authenticate with Google Cloud Storage.
1 property
1 required
CIAppResponseStatus
string
The status of the response.
ObservabilityPipelineRenameFieldsProcessor
object
The renamefields processor changes field names.
5 properties
5 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedact
object
Configuration for partially redacting matched sensitive data.
2 properties
2 required
ObservabilityPipelineGoogleCloudStorageDestinationAcl
string
Access control list setting for objects written to the bucket.
ObservabilityPipelineFilterProcessor
object
The filter processor allows conditional processing of logs based on a Datadog search query. Logs that match the include query are passed through; others are di…
4 properties
4 required
ObservabilityPipelineAmazonDataFirehoseSourceType
string
The source type. The value should always be amazondatafirehose.
ObservabilityPipelineSumoLogicDestination
object
The sumologic destination forwards logs to Sumo Logic.
8 properties
3 required
CIAppPipelinesBucketResponse
object
Bucket values.
2 properties
AzureStorageDestinationType
string
The destination type. The value should always be azurestorage.
ObservabilityPipelineMetricValue
Specifies how the value of the generated metric is computed.
ObservabilityPipelineQuotaProcessorOverride
object
Defines a custom quota limit that applies to specific log events based on matching field values.
2 properties
2 required
CIAppPipelineEventJobLevel
string
Used to distinguish between pipelines, stages, jobs, and steps.
CIAppPipelinesQueryFilter
object
The search and filter query settings.
3 properties
ObservabilityPipelineRsyslogDestination
object
The rsyslog destination forwards logs to an external rsyslog server over TCP or UDP using the syslog protocol.
5 properties
3 required
ObservabilityPipelineGoogleChronicleDestinationType
string
The destination type. The value should always be googlechronicle.
ObservabilityPipelineDedupeProcessor
object
The dedupe processor removes duplicate fields in log events.
6 properties
6 required
ObservabilityPipelineAmazonS3DestinationType
string
The destination type. Always amazons3.
ObservabilityPipelineGoogleChronicleDestinationEncoding
string
The encoding format for the logs sent to Chronicle.
ObservabilityPipelineSensitiveDataScannerProcessorScopeInclude
object
Includes only specific fields for sensitive data scanning.
2 properties
2 required
CIAppAggregateSortType
string
The type of sorting algorithm.
ObservabilityPipelineMetadataEntry
object
A custom metadata entry.
2 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorActionHash
object
Configuration for hashing matched sensitive values.
2 properties
1 required
ObservabilityPipelineParseGrokProcessor
object
The parsegrok processor extracts structured fields from unstructured log messages using Grok patterns.
6 properties
5 required
CIAppPipelineEventPreviousPipeline
object
If the pipeline is a retry, this should contain the details of the previous attempt.
2 properties
1 required
ObservabilityPipelineSumoLogicDestinationType
string
The destination type. The value should always be sumologic.
ObservabilityPipelineFilterProcessorType
string
The processor type. The value should always be filter.
ObservabilityPipelineRemoveFieldsProcessor
object
The removefields processor deletes specified fields from logs.
5 properties
5 required
ObservabilityPipelineThrottleProcessorType
string
The processor type. The value should always be throttle.
CIAppGroupByMissingString
string
The missing value to use if there is a string valued facet.
CIAppPipelineEvent
object
Object description of a pipeline event after being processed and stored by Datadog.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorScopeExcludeTarget
string
Excludes specific fields from processing.
CIAppHostInfo
object
Contains information of the host running the pipeline, stage, job, or step.
4 properties
ObservabilityPipelineSentinelOneDestination
object
The sentinelone destination sends logs to SentinelOne.
4 properties
4 required
CIAppPipelineEventsRequest
object
The request for a pipelines search.
4 properties
CIAppCreatePipelineEventRequestAttributes
object
Attributes of the pipeline event to create.
4 properties
1 required
ObservabilityPipelineSensitiveDataScannerProcessorAction
Defines what action to take when sensitive data is matched.
ObservabilityPipelineParseGrokProcessorRule
object
A Grok parsing rule used in the parsegrok processor. Each rule defines how to extract structured fields from a specific log field using Grok patterns.
3 properties
3 required
ObservabilityPipelineDedupeProcessorType
string
The processor type. The value should always be dedupe.
ObservabilityPipelineSampleProcessorType
string
The processor type. The value should always be sample.
ObservabilityPipelineSyslogNgDestinationType
string
The destination type. The value should always be syslogng.
ObservabilityPipelineEnrichmentTableProcessorType
string
The processor type. The value should always be enrichmenttable.
ObservabilityPipelineSentinelOneDestinationRegion
string
The SentinelOne region to send logs to.
ObservabilityPipelineEnrichmentTableFileEncodingType
string
Specifies the encoding format (e.g., CSV) used for enrichment tables.
UsageTimeSeriesType
string
Type of usage data.
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptionsDirection
string
Indicates whether to redact characters from the first or last part of the matched value.
CIAppAggregateBucketValueTimeseries
array
A timeseries array.
ObservabilityPipelineGeneratedMetricIncrementByOne
object
Strategy that increments a generated metric by one for each matching event.
1 property
1 required
ObservabilityPipelineElasticsearchDestinationType
string
The destination type. The value should always be elasticsearch.
ObservabilityPipelineAmazonS3Source
object
The amazons3 source ingests logs from an Amazon S3 bucket. It supports AWS authentication and TLS encryption.
5 properties
3 required
ObservabilityPipelineSyslogSourceMode
string
Protocol used by the syslog source to receive messages.
ListPipelinesResponseMeta
object
Metadata about the response.
1 property
ObservabilityPipelineAddFieldsProcessor
object
The addfields processor adds static key-value fields to logs.
5 properties
5 required
ObservabilityPipelineLogstashSource
object
The logstash source ingests logs from a Logstash forwarder.
3 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptions
object
Controls how partial redaction is applied, including character count and direction.
2 properties
2 required
ObservabilityPipelineAddEnvVarsProcessorType
string
The processor type. The value should always be addenvvars.
ObservabilityPipelineGeneratedMetricIncrementByField
object
Strategy that increments a generated metric based on the value of a log field.
2 properties
2 required
ObservabilityPipelineSplunkHecDestinationType
string
The destination type. Always splunkhec.
ObservabilityPipelineFluentdSourceType
string
The source type. The value should always be fluentd.
ObservabilityPipelineNewRelicDestinationRegion
string
The New Relic region.
CIAppGroupByTotalString
string
A string to use as the key value for the total bucket.
CIAppAggregateBucketValue
A bucket value, can either be a timeseries or a single value.
ValidationError
object
Represents a single validation error, including a human-readable title and metadata.
2 properties
2 required
ObservabilityPipelineAddFieldsProcessorType
string
The processor type. The value should always be addfields.
ObservabilityPipelineEnrichmentTableFileEncoding
object
File encoding format.
3 properties
3 required
ObservabilityPipelineOcsfMapperProcessorMappingMapping
Defines a single mapping rule for transforming logs into the OCSF schema.
ObservabilityPipelineGeneratedMetricIncrementByOneStrategy
string
Increments the metric by 1 for each matching event.
ObservabilityPipelineSplunkHecSource
object
The splunkhec source implements the Splunk HTTP Event Collector (HEC) API.
3 properties
2 required
ObservabilityPipelineSyslogNgSource
object
The syslogng source listens for logs over TCP or UDP from a syslog-ng server using the syslog protocol.
4 properties
3 required
CIAppGroupByHistogram
object
Used to perform a histogram computation (only for measure facets). At most, 100 buckets are allowed, the number of buckets is (max - min)/interval.
3 properties
3 required
ObservabilityPipelineSensitiveDataScannerProcessorKeywordOptions
object
Configuration for keywords used to reinforce sensitive data pattern detection.
2 properties
2 required
APIErrorResponse
object
API error response.
1 property
1 required
ObservabilityPipelineAmazonOpenSearchDestination
object
The amazonopensearch destination writes logs to Amazon OpenSearch.
5 properties
4 required
ObservabilityPipelineEnrichmentTableFile
object
Defines a static enrichment table loaded from a CSV file.
4 properties
4 required
ObservabilityPipelineAmazonS3Destination
object
The amazons3 destination sends your logs in Datadog-rehydratable format to an Amazon S3 bucket for archiving.
9 properties
6 required
ObservabilityPipelineSumoLogicSourceType
string
The source type. The value should always be sumologic.
CIAppPipelinesAnalyticsAggregateResponse
object
The response object for the pipeline events aggregate API endpoint.
3 properties
ObservabilityPipelineAmazonS3SourceType
string
The source type. Always amazons3.
ObservabilityPipelineEnrichmentTableFileSchemaItems
object
Describes a single column and its type in an enrichment table schema.
2 properties
2 required
ObservabilityPipelineNewRelicDestinationType
string
The destination type. The value should always be newrelic.
ObservabilityPipelineElasticsearchDestinationApiVersion
string
The Elasticsearch API version to use. Set to auto to auto-detect.
ObservabilityPipelineAmazonOpenSearchDestinationAuthStrategy
string
The authentication strategy to use.
CIAppPipelineLevel
string
Pipeline execution level.
MicrosoftSentinelDestination
object
The microsoftsentinel destination forwards logs to Microsoft Sentinel.
7 properties
7 required
CIAppAggregationFunction
string
An aggregation function.
ObservabilityPipelineEnrichmentTableGeoIp
object
Uses a GeoIP database to enrich logs based on an IP field.
3 properties
3 required
ObservabilityPipelineFieldValue
object
Represents a static key-value pair used in various processors.
2 properties
2 required
HTTPCIAppError
object
List of errors.
3 properties
CIAppPipelineEventFinishedPipeline
object
Details of a finished pipeline.
20 properties
8 required
ObservabilityPipelineDataAttributes
object
Defines the pipeline’s name and its components (sources, processors, and destinations).
2 properties
2 required
ObservabilityPipelineEnrichmentTableProcessor
object
The enrichmenttable processor enriches logs using a static CSV file or GeoIP database.
7 properties
5 required
ObservabilityPipelineGeneratedMetricMetricType
string
Type of metric to create.
ValidationErrorMeta
object
Describes additional metadata for validation errors, including field names and error messages.
3 properties
1 required
ObservabilityPipelineAddEnvVarsProcessorVariable
object
Defines a mapping between an environment variable and a log field.
2 properties
2 required
CIAppAggregateBucketValueTimeseriesPoint
object
A timeseries point.
2 properties
CIAppQueryOptions
object
Global query options that are used during the query. Only supply timezone or time offset, not both. Otherwise, the query fails.
2 properties
ObservabilityPipelineDatadogAgentSourceType
string
The source type. The value should always be datadogagent.
TagsEventAttribute
array
Array of tags associated with your event.
ObservabilityPipelineSensitiveDataScannerProcessorScope
Determines which parts of the log the pattern-matching rule should be applied to.
ObservabilityPipelineSensitiveDataScannerProcessorScopeExclude
object
Excludes specific fields from sensitive data scanning.
2 properties
2 required
ObservabilityPipelinePipelineKafkaSourceSaslMechanism
string
SASL mechanism used for Kafka authentication.
ObservabilityPipelineFluentBitSourceType
string
The source type. The value should always be fluentbit.
UsageObservabilityPipelinesResponse
object
Observability Pipelines usage response.
1 property
UsageAttributesObject
object
Usage attributes data.
6 properties
CIAppResponseMetadataWithPagination
object
The metadata associated with a request.
5 properties
CIAppCIErrorDomain
string
Error category used to differentiate between issues related to the developer or provider environments.
ObservabilityPipelineSyslogNgDestination
object
The syslogng destination forwards logs to an external syslog-ng server over TCP or UDP using the syslog protocol.
5 properties
3 required
ObservabilityPipelineQuotaProcessorType
string
The processor type. The value should always be quota.
ObservabilityPipelineSentinelOneDestinationType
string
The destination type. The value should always be sentinelone.
ObservabilityPipelineGoogleCloudStorageDestinationType
string
The destination type. Always googlecloudstorage.
ObservabilityPipelineEnrichmentTableFileKeyItems
object
Defines how to map log fields to enrichment table columns during lookups.
3 properties
3 required
CIAppPipelineEventPipelineLevel
string
Used to distinguish between pipelines, stages, jobs, and steps.
CIAppAggregateBucketValueSingleString
string
A single string value.
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactAction
string
Action type that redacts part of the sensitive data while preserving a configurable number of characters, typically used for masking purposes (e.g., show last…
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPattern
object
Specifies a pattern from Datadog’s sensitive data detection library to match known sensitive data types.
2 properties
2 required
CIAppCreatePipelineEventRequestData
object
Data of the pipeline event to create.
2 properties
ObservabilityPipelineSpecData
object
Contains the the pipeline configuration.
2 properties
2 required
CIAppPipelineEventStageLevel
string
Used to distinguish between pipelines, stages, jobs and steps.
ObservabilityPipelineDatadogAgentSource
object
The datadogagent source collects logs from the Datadog Agent.
3 properties
2 required
ObservabilityPipelineReduceProcessorType
string
The processor type. The value should always be reduce.
ObservabilityPipelineParseJSONProcessorType
string
The processor type. The value should always be parsejson.
ObservabilityPipelineAmazonOpenSearchDestinationAuth
object
Authentication settings for the Amazon OpenSearch destination. The strategy field determines whether basic or AWS-based authentication is used.
5 properties
1 required
ObservabilityPipelineHttpServerSourceType
string
The source type. The value should always be httpserver.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactAction
string
Action type that completely replaces the matched sensitive data with a fixed replacement string to remove all visibility.
ObservabilityPipelineThrottleProcessor
object
The throttle processor limits the number of events that pass through over a given time window.
7 properties
6 required
ObservabilityPipelineTls
object
Configuration for enabling TLS encryption between the pipeline component and external services.
3 properties
1 required
CIAppPipelineEventAttributes
object
JSON object containing all event attributes and their associated values.
3 properties
CIAppCreatePipelineEventRequestDataType
string
Type of the event.
ValidationResponse
object
Response containing validation errors.
1 property
ObservabilityPipelineEnrichmentTableFileSchemaItemsType
string
Declares allowed data types for enrichment table columns.
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternOptions
object
Options for selecting a predefined library pattern and enabling keyword support.
2 properties
1 required
ObservabilityPipelineDatadogLogsDestination
object
The datadoglogs destination forwards logs to Datadog Log Management.
3 properties
3 required
ObservabilityPipelineAmazonS3DestinationStorageClass
string
S3 storage class.
CIAppQueryPageOptions
object
Paging attributes for listing events.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternOptions
object
Options for defining a custom regex pattern.
1 property
1 required
ObservabilityPipelineDecoding
string
The decoding format used to interpret incoming logs.
ObservabilityPipelineSumoLogicDestinationHeaderCustomFieldsItem
object
Single key-value pair used as a custom log header for Sumo Logic.
2 properties
2 required
ObservabilityPipelineRenameFieldsProcessorField
object
Defines how to rename a field in log events.
3 properties
3 required
ObservabilityPipelineGooglePubSubSource
object
The googlepubsub source ingests logs from a Google Cloud Pub/Sub subscription.
7 properties
6 required
ObservabilityPipelineReduceProcessorMergeStrategyStrategy
string
The merge strategy to apply.
ObservabilityPipelineAwsAuth
object
AWS authentication credentials used for accessing AWS services such as S3. If omitted, the system’s default credentials are used (for example, the IAM role and…
3 properties
ObservabilityPipelineConfigProcessorItem
A processor for the pipeline.
ObservabilityPipelineQuotaProcessorLimitEnforceType
string
Unit for quota enforcement in bytes for data size or events for count.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactOptions
object
Configuration for fully redacting sensitive data.
1 property
1 required
ObservabilityPipelineSyslogNgSourceType
string
The source type. The value should always be syslogng.
ObservabilityPipelineAddEnvVarsProcessor
object
The addenvvars processor adds environment variable values to log events.
5 properties
5 required
ObservabilityPipelineSensitiveDataScannerProcessorPattern
Pattern detection configuration for identifying sensitive data using either a custom regex or a library reference.
CIAppPipelineEventParentPipeline
object
If the pipeline is triggered as child of another pipeline, this should contain the details of the parent pipeline.
2 properties
1 required
ObservabilityPipelineOcsfMapperProcessorType
string
The processor type. The value should always be ocsfmapper.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedact
object
Configuration for completely redacting matched sensitive data.
2 properties
2 required
CIAppPipelinesAggregateRequest
object
The object sent with the request to retrieve aggregation buckets of pipeline events from your organization.
4 properties
CIAppSort
string
Sort parameters when querying events.
CIAppResponsePage
object
Paging attributes.
1 property
ObservabilityPipelineReduceProcessor
object
The reduce processor aggregates and merges logs based on matching keys and merge strategies.
6 properties
6 required
ObservabilityPipelineGenerateMetricsProcessorType
string
The processor type. Always generatedatadogmetrics.
CIAppPipelineEventStep
object
Details of a CI step.
19 properties
8 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeAll
object
Applies scanning across all available fields.
1 property
1 required
ObservabilityPipelineParseGrokProcessorRuleSupportRule
object
The Grok helper rule referenced in the parsing rules.
2 properties
2 required
ObservabilityPipelineOcsfMapperProcessor
object
The ocsfmapper processor transforms logs into the OCSF schema using a predefined mapping configuration.
5 properties
5 required
ObservabilityPipelineRsyslogDestinationType
string
The destination type. The value should always be rsyslog.
ObservabilityPipelineSplunkTcpSourceType
string
The source type. Always splunktcp.
ObservabilityPipelineKafkaSourceLibrdkafkaOption
object
Represents a key-value pair used to configure low-level librdkafka client options for Kafka sources, such as timeouts, buffer sizes, and security settings.
2 properties
2 required
UsageDataObject
object
Usage data.
3 properties
ObservabilityPipeline
object
Top-level schema representing a pipeline.
1 property
1 required
ObservabilityPipelineQuotaProcessorOverflowAction
string
The action to take when the quota is exceeded. Options: - drop: Drop the event. - noaction: Let the event pass through. - overflowrouting: Route to an overflow…
ObservabilityPipelineConfigDestinationItem
A destination for the pipeline.
CIAppPipelineEventPipeline
Details of the top level pipeline, build, or workflow of your CI.
ObservabilityPipelineSensitiveDataScannerProcessorScopeOptions
object
Fields to which the scope rule applies.
1 property
1 required
ObservabilityPipelineOpenSearchDestination
object
The opensearch destination writes logs to an OpenSearch cluster.
4 properties
3 required
CIAppPipelineEventStepStatus
string
The final status of the step.
CIAppResponseLinks
object
Links attributes.
1 property
CIAppPipelineEventJobStatus
string
The final status of the job.
ObservabilityPipelineSplunkHecSourceType
string
The source type. Always splunkhec.
CIAppSortOrder
string
The order to use, ascending or descending.
CIAppGroupByTotalBoolean
boolean
If set to true, creates an additional bucket labeled "$facettotal".
CIAppResponseMetadata
object
The metadata associated with a request.
4 properties
HTTPCIAppErrors
object
Errors occurred.
1 property
ObservabilityPipelineKafkaSourceType
string
The source type. The value should always be kafka.
ObservabilityPipelineSensitiveDataScannerProcessorScopeAllTarget
string
Applies the rule to all fields.
ObservabilityPipelineGoogleCloudStorageDestination
object
The googlecloudstorage destination stores logs in a Google Cloud Storage (GCS) bucket. It requires a bucket name, GCP authentication, and metadata fields.
9 properties
7 required
ObservabilityPipelineSumoLogicDestinationEncoding
string
The output encoding format.
ObservabilityPipelineQuotaProcessor
object
The Quota Processor measures logging traffic for logs that match a specified filter. When the configured daily quota is met, the processor can drop or alert.
11 properties
7 required
ObservabilityPipelineConfigSourceItem
A data source for the pipeline.
ObservabilityPipelineGoogleCloudStorageDestinationStorageClass
string
Storage class used for objects stored in GCS.
ObservabilityPipelineConfig
object
Specifies the pipeline's configuration, including its sources, processors, and destinations.
3 properties
2 required
ObservabilityPipelineParseGrokProcessorType
string
The processor type. The value should always be parsegrok.
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Datadog publishes across the network.